Trojan.Pakes et Pipas.A, comment sen débarrasser ? - Sécurité - Windows & Software
Marsh Posté le 14-04-2006 à 16:35:27
Pour Trojan.Pakes   
 
Telecharge ca 
http://downloads.subratam.org/Fixwareout.exe  
Installer le et suit la procédure,  
puis refait un scan avec ewido en mode sans échec, et de nouveau en mode normal.  
 
Pour Pipas.A 
 
| Citation : La clé de registre suivante est ajoutée afin de lancer le processus après le redémarrage:  | 
 
 
http://www.avira.com/fr/threats/se [...] pas.a.html 
http://forum.telecharger.01net.com [...] ges-1.html 
 
Si tu ne comprend pas ce tout ce que tu fait... alors ====> Bienvenue dans le monde du pc (et de m$)
Marsh Posté le 14-04-2006 à 17:24:35
Ok, voilà ce que j'ai comme rapport de Fixwareout: 
 
  
Fixwareout ver 1.003 
Last edited 04/09/2006 
Post this report in the forums please  
  
Reg Entries that were deleted  
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\inhmd 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\xedocne 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\gib_ogol 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\repiwoh 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\llun 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\23plhps 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\mgcppp 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\tesvaf 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\32refaselif 
... 
 
Microsoft (R) Windows Script Host Version 5.6 
Random Runs removed from HKLM  
"dmhni.exe"=- 
... 
  
PLEASE NOTE, There WILL be LEGIT FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE. 
Example ipsec6.exe is lagitamate 
  
»»»»» Search by size and names...  
  
»»»»» Misc files  
  
»»»»» Checking for older varients covered by the Rem3 tool
Marsh Posté le 14-04-2006 à 17:30:39
Slt, 
 
Télécharge SilentRunners.vbs. 
Double clique le, et lorsqu'il a terminé son scan, copie/colle son log.
Marsh Posté le 14-04-2006 à 18:24:11
Juste un détail: depuis que j'ai executé Fixwareout j'arrive plus à démarrer en mode sans échec (et le démarrage de ma session Windows me semble plus long, en particulier j'ai un écran bleu de quelques secondes qu'il ne me semblais pas avoir avant)...
Marsh Posté le 14-04-2006 à 18:28:04
Pour SilentRunner: 
 
"Silent Runners.vbs", revision 44, http://www.silentrunners.org/ 
Operating System: Windows XP SP2 
Output limited to non-default values, except where indicated by "{++}" 
 
 
Startup items buried in registry: 
--------------------------------- 
 
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} 
"CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS] 
"Creative Detector" = ""C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R" ["Creative Technology Ltd"] 
"LDM" = "\Program\BackWeb-8876480.exe" [file not found] 
"(Default)" = (empty string) 
"ATI Remote Control" = "C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe" ["ATI Technologies Inc."] 
"Skype" = ""C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized" ["Skype Technologies S.A."] 
"LogitechSoftwareUpdate" = ""C:\Program Files\Logitech\Video\ManifestEngine.exe" boot" ["Logitech Inc."] 
"updateMgr" = ""C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1" ["Adobe Systems Incorporated"] 
 
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} 
"SunJavaUpdateSched" = "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [null data] 
"IAAnotif" = "C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe" ["Intel Corporation"] 
"zBrowser Launcher" = "C:\Program Files\Logitech\iTouch\iTouch.exe" ["Logitech Inc."] 
"CTSysVol" = "C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r" ["Creative Technology Ltd"] 
"CTDVDDET" = ""C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE"" ["Creative Technology Ltd"] 
"CTHelper" = "CTHELPER.EXE" ["Creative Technology Ltd"] 
"UpdReg" = "C:\WINDOWS\UpdReg.EXE" ["Creative Technology Ltd."] 
"Logitech Utility" = "Logi_MwX.Exe" ["Logitech Inc."] 
"DVDLauncher" = ""C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"" ["CyberLink Corp."] 
"NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"] 
"InCD" = "C:\Program Files\Ahead\InCD\InCD.exe" ["Nero AG"] 
"EEventManager" = "C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe" [empty string] 
"ATIPTA" = ""C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"" ["ATI Technologies, Inc."] 
"ATICCC" = ""C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime" [null data] 
"PMCS" = "C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe -host -clearDebug" [null data] 
"PinnacleDriverCheck" = "C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg" [empty string] 
"LVCOMSX" = "C:\WINDOWS\system32\LVCOMSX.EXE" ["Logitech Inc."] 
"LogitechCameraAssistant" = "C:\Program Files\Logitech\Video\CameraAssistant.exe" ["Logitech Inc."] 
"LogitechVideo[inspector]" = "C:\Program Files\Logitech\Video\InstallHelper.exe /inspect" ["Logitech Inc."] 
"LogitechCameraService(E)" = "C:\WINDOWS\system32\ElkCtrl.exe /automation" ["Logitech Inc."] 
"MaxtorOneTouch" = "C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe" ["Maxtor Corporation"] 
"RetroExpress" = "C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe /h" [null data] 
"Picasa Media Detector" = "C:\Program Files\Picasa2\PicasaMediaDetector.exe" ["Google Inc."] 
"MXOBG" = "C:\WINDOWS\MXOALDR.EXE" ["Cypress Semiconductor"] 
"Windows Defender" = ""C:\Program Files\Windows Defender\MSASCui.exe" -hide" [MS] 
"TkBellExe" = ""C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe"  -osboot" ["RealNetworks, Inc."] 
"iTunesHelper" = ""C:\Program Files\iTunes\iTunesHelper.exe"" ["Apple Computer, Inc."] 
"QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."] 
"ccApp" = ""C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"" ["Symantec Corporation"] 
"Norton Ghost 10.0" = ""C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe"" ["Symantec Corporation"] 
 
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ 
{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided) 
  -> {HKLM...CLSID} = (no title provided) 
                   \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"] 
{9ECB9560-04F9-4bbc-943D-298DDF1699E1}\(Default) = "Norton Internet Security 2006" 
  -> {HKLM...CLSID} = "CNisExtBho Class" 
                   \InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll" ["Symantec Corporation"] 
{A8F38D8D-E480-4D52-B7A2-731BB6995FDD}\(Default) = "NAV Helper" 
  -> {HKLM...CLSID} = "CNavExtBho Class" 
                   \InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"] 
 
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ 
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal" 
  -> {HKLM...CLSID} = "HyperTerminal Icon Ext" 
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."] 
"{BB7DF450-F119-11CD-8465-00AA00425D90}" = "Microsoft Access Custom Icon Handler" 
  -> {HKLM...CLSID} = (no title provided) 
                   \InProcServer32\(Default) = "C:\Program Files\msaccrt\Access 97\soa800.dll" [MS] 
"{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices" 
  -> {HKLM...CLSID} = "Portable Media Devices" 
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS] 
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu" 
  -> {HKLM...CLSID} = "Portable Media Devices Menu" 
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS] 
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player" 
  -> {HKLM...CLSID} = "RealOne Player Context Menu Class" 
                   \InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."] 
"{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}" = "iTunes" 
  -> {HKLM...CLSID} = "iTunes" 
                   \InProcServer32\(Default) = "C:\Program Files\iTunes\iTunesMiniPlayer.dll" ["Apple Computer, Inc."] 
"{950FF917-7A57-46BC-8017-59D9BF474000}" = "Shell Extension for CDRW" 
  -> {HKLM...CLSID} = "Shell Extension for CDRW" 
                   \InProcServer32\(Default) = "C:\Program Files\Ahead\InCD\incdshx.dll" ["Nero AG"] 
"{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler" 
  -> {HKLM...CLSID} = "Microsoft Office Outlook" 
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL" [MS] 
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler" 
  -> {HKLM...CLSID} = "Outlook File Icon Extension" 
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL" [MS] 
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler" 
  -> {HKLM...CLSID} = (no title provided) 
                   \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\OFFICE11\msohev.dll" [MS] 
"{5E2121EE-0300-11D4-8D3B-444553540000}" = "Catalyst Context Menu extension" 
  -> {HKLM...CLSID} = "SimpleShlExt Class" 
                   \InProcServer32\(Default) = "C:\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll" [empty string] 
"{7059DA7A-7E60-11d2-A355-00C04FB9D26E}" = "Maxtor Locked Drives" 
  -> {HKLM...CLSID} = "Maxtor Locked Drives" 
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\MXONmSpace.dll" [null data] 
"{21569614-B795-46b1-85F4-E737A8DC09AD}" = "Shell Search Band" 
  -> {HKLM...CLSID} = "Shell Search Band" 
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS] 
"{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders" 
  -> {HKLM...CLSID} = "Mes dossiers de partage" 
                   \InProcServer32\(Default) = "C:\PROGRA~1\MSNMES~1\fsshext.dll" [MS] 
"{EE337094-9F50-4B8C-9B53-C00F52A3289B}" = "GF Shell Extension" 
  -> {HKLM...CLSID} = "GFIconShellEx Class" 
                   \InProcServer32\(Default) = "C:\Program Files\Fichiers communs\onOne Software Shared\lt_lib_gf_iconShellEx.dll" ["onOne Software"] 
 
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\ 
INFECTION WARNING! "{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}" = "Microsoft AntiMalware ShellExecuteHook" 
  -> {HKLM...CLSID} = "Microsoft AntiMalware ShellExecuteHook" 
                   \InProcServer32\(Default) = "C:\PROGRA~1\WIFD1F~1\MpShHook.dll" [MS] 
INFECTION WARNING! "{54D9498B-CF93-414F-8984-8CE7FDE0D391}" = "ewido shell guard" 
  -> {HKLM...CLSID} = "CShellExecuteHookImpl Object" 
                   \InProcServer32\(Default) = "C:\Program Files\ewido anti-malware\shellhook.dll" ["TODO: <Firmenname>"] 
 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\ 
"System" = (value not set) 
 
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ 
INFECTION WARNING! AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."] 
 
HKLM\Software\Classes\PROTOCOLS\Filter\ 
INFECTION WARNING! text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}" 
  -> {HKLM...CLSID} = (no title provided) 
                   \InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [MS] 
 
HKLM\Software\Classes\Folder\shellex\ColumnHandlers\ 
{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info" 
  -> {HKLM...CLSID} = "PDF Shell Extension" 
                   \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."] 
 
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ 
ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}" 
  -> {HKLM...CLSID} = "Ctest Object" 
                   \InProcServer32\(Default) = "C:\Program Files\ewido anti-malware\context.dll" ["ewido networks"] 
Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{FAD61B3D-699D-49B2-BE16-7F82CB4C59CA}" 
  -> {HKLM...CLSID} = "IEContextMenu Class" 
                   \InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"] 
 
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ 
ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}" 
  -> {HKLM...CLSID} = "Ctest Object" 
                   \InProcServer32\(Default) = "C:\Program Files\ewido anti-malware\context.dll" ["ewido networks"] 
 
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ 
Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{FAD61B3D-699D-49B2-BE16-7F82CB4C59CA}" 
  -> {HKLM...CLSID} = "IEContextMenu Class" 
                   \InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"] 
 
 
Default executables: 
-------------------- 
 
HKCU\Software\Classes\.bat\(Default) = (value not set) 
 
HKCU\Software\Classes\.cmd\(Default) = (value not set) 
 
HKCU\Software\Classes\.com\(Default) = (value not set) 
 
HKCU\Software\Classes\.exe\(Default) = (value not set) 
 
HKCU\Software\Classes\.hta\(Default) = (value not set) 
 
 
Active Desktop and Wallpaper: 
----------------------------- 
 
Active Desktop is disabled at this entry: 
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState 
 
 
Startup items in "Niko" & "All Users" startup folders: 
------------------------------------------------------ 
 
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage 
"ATI CATALYST System Tray" -> shortcut to: "C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe SystemTray" [null data] 
"DataViz Inc Messenger" -> shortcut to: "C:\Program Files\Fichiers communs\DataViz\DvzIncMsgr.exe" ["DataViz, Inc."] 
"EPSON Status Monitor 3 Environment Check 2" -> shortcut to: "C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE" ["SEIKO EPSON CORPORATION"] 
"Google Updater" -> shortcut to: "C:\Program Files\Google\Google Updater\1.1.433.23491\GoogleUpdater.exe -systray -startup" [null data] 
"HotSync Manager" -> shortcut to: "C:\Program Files\palmOne\Hotsync.exe -logon" ["PalmSource, Inc"] 
"Lancement rapide d'Adobe Reader" -> shortcut to: "C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe" ["Adobe Systems Incorporated"] 
"Loadout Manager" -> shortcut to: "C:\Program Files\Belkin\Nostromo\nost_LM.exe -startup" [empty string] 
"Logitech Desktop Messenger" -> shortcut to: "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe /start" ["Logitech"] 
"MonacoGamma" -> shortcut to: "C:\Program Files\Monaco Systems\MonacoEZcolor 2.6\MonacoGamma.exe -StartUp -All" ["Monaco Systems"] 
"Service Manager" -> shortcut to: "C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe /n" [MS] 
"TabUserW.exe" -> shortcut to: "C:\WINDOWS\system32\WTablet\TabUserW.exe" ["Wacom Technology, Corp."] 
 
 
Enabled Scheduled Tasks: 
------------------------ 
 
"MP Scheduled Scan" -> launches: "C:\Program Files\Windows Defender\MpCmdRun.exe Scan -ScanType config -Privileges restricted" [MS] 
"Norton AntiVirus - Effectuer une analyse complète du système - Niko" -> launches: "C:\PROGRA~1\NORTON~2\NORTON~1\Navw32.exe /TASK:"C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Tasks\mycomp.sca"" ["Symantec Corporation"] 
"Norton AntiVirus - Exécuter Norton QuickScan - Niko" -> launches: "C:\PROGRA~1\NORTON~2\NORTON~1\Navw32.exe /TASK:"C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Tasks\quick.sca"" ["Symantec Corporation"] 
 
 
Winsock2 Service Provider DLLs: 
------------------------------- 
 
Namespace Service Providers 
 
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] 
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS] 
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] 
 
Transport Service Providers 
 
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: 
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 26 
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05 
 
 
Toolbars, Explorer Bars, Extensions: 
------------------------------------ 
 
Toolbars 
 
HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\ 
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" 
  -> {HKLM...CLSID} = "&Google" 
                   \InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."] 
 
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ 
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}" 
  -> {HKLM...CLSID} = "Norton Internet Security 2006" 
                   \InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll" ["Symantec Corporation"] 
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" 
  -> {HKLM...CLSID} = "&Google" 
                   \InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."] 
"{C4069E3A-68F1-403E-B40E-20066696354B}" 
  -> {HKLM...CLSID} = "Norton AntiVirus" 
                   \InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"] 
 
HKLM\Software\Microsoft\Internet Explorer\Toolbar\ 
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = (no title provided) 
  -> {HKLM...CLSID} = "&Google" 
                   \InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."] 
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}" = "Norton Internet Security 2006" 
  -> {HKLM...CLSID} = "Norton Internet Security 2006" 
                   \InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll" ["Symantec Corporation"] 
"{C4069E3A-68F1-403E-B40E-20066696354B}" = "Norton AntiVirus" 
  -> {HKLM...CLSID} = "Norton AntiVirus" 
                   \InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"] 
 
Explorer Bars 
 
Dormant Explorer Bars in "View, Explorer Bar" menu 
 
HKLM\Software\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Rechercher" 
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar] 
InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL" [MS] 
 
Extensions (Tools menu items, main toolbar menu buttons) 
 
HKLM\Software\Microsoft\Internet Explorer\Extensions\ 
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ 
"MenuText" = "Console Java (Sun)" 
"CLSIDExtension" = "{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" 
 
{5E638779-1818-4754-A595-EF1C63B87A56}\ 
"ButtonText" = "Express Cleanup" 
"MenuText" = "Express Cleanup" 
"Exec" = "C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk" [null data] 
 
{92780B25-18CC-41C8-B9BE-3C9C571A8263}\ 
"ButtonText" = "Recherche" 
 
{FB5F1910-F110-11D2-BB9E-00C04F795683}\ 
"ButtonText" = "Messenger" 
"MenuText" = "Windows Messenger" 
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS] 
 
 
Miscellaneous IE Hijack Points 
------------------------------ 
 
C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings" ) 
 
Added lines (compared with English-language version): 
[Strings]: SAFESITE_VALUE="http://home.microsoft.com/intl/fr/" 
 
Missing lines (compared with English-language version): 
[Strings]: 1 line 
 
 
Running Services (Display Name, Service Name, Path {Service DLL}): 
------------------------------------------------------------------ 
 
Canon Camera Access Library 8, CCALib8, "C:\Program Files\Canon\CAL\CALMAIN.exe" ["Canon Inc."] 
Creative Service for CDROM Access, Creative Service for CDROM Access, "C:\WINDOWS\system32\CTsvcCDA.EXE" ["Creative Technology Ltd"] 
EPSON Printer Status Agent2, EPSONStatusAgent2, "C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe" ["SEIKO EPSON CORPORATION"] 
EpsonBidirectionalService, EpsonBidirectionalService, "C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe" [null data] 
ewido security suite control, ewido security suite control, "C:\Program Files\ewido anti-malware\ewidoctrl.exe" ["ewido networks"] 
ewido security suite guard, ewido security suite guard, "C:\Program Files\ewido anti-malware\ewidoguard.exe" ["ewido networks"] 
GEARSecurity, GEARSecurity, "C:\WINDOWS\System32\GEARSec.exe" ["GEAR Software"] 
HTTP SSL, HTTPFilter, "C:\WINDOWS\System32\svchost.exe -k HTTPFilter" {"C:\WINDOWS\System32\w3ssl.dll" [MS]} 
IAA Event Monitor, IAANTMon, "C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe" ["Intel Corporation"] 
InCD Helper, InCDsrv, "C:\Program Files\Ahead\InCD\InCDsrv.exe" ["Nero AG"] 
iPodService, iPodService, "C:\Program Files\iPod\bin\iPodService.exe" ["Apple Computer, Inc."] 
Logitech Process Monitor, LVPrcSrv, "c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe" ["Logitech Inc."] 
MSSQL$PINNACLESYS, MSSQL$PINNACLESYS, "C:\Program Files\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe -sPINNACLESYS" [MS] 
Norton Ghost, Norton Ghost, "C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\VProSvc.exe" ["Symantec Corporation"] 
Norton Protection Center Service, NSCService, ""C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE"" ["Symantec Corporation"] 
Norton UnErase Protection, NProtectService, "C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE" ["Symantec Corporation"] 
Pinnacle Systems Media Service, PinnacleSys.MediaServer, "c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe" [null data] 
Pinnacle Systems tvtv Spooler, EpgSpooler, "c:\progra~1\pinnacle\mediac~1\epgspo~2.exe" [null data] 
Planificateur LiveUpdate automatique, Planificateur LiveUpdate automatique, ""C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"" ["Symantec Corporation"] 
Retrospect Express HD Launcher, RetroExpLauncher, "C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe" ["Dantz Development Corporation"] 
Service d'application d'assistance IPv6, 6to4, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\6to4svc.dll" [MS]} 
Service Norton AntiVirus Auto-Protect, navapsvc, ""C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe"" ["Symantec Corporation"] 
Speed Disk service, Speed Disk service, "C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE" ["Symantec Corporation"] 
Symantec Core LC, Symantec Core LC, "C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe" ["Symantec Corporation"] 
Symantec Event Manager, ccEvtMgr, ""C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe"" ["Symantec Corporation"] 
Symantec Network Drivers Service, SNDSrvc, ""C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe"" ["Symantec Corporation"] 
Symantec Network Proxy, ccProxy, ""C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe"" ["Symantec Corporation"] 
Symantec Settings Manager, ccSetMgr, ""C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe"" ["Symantec Corporation"] 
Symantec SPBBCSvc, SPBBCSvc, ""C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe"" ["Symantec Corporation"] 
TabletService, TabletService, "C:\WINDOWS\system32\Tablet.exe" ["Wacom Technology, Corp."] 
Windows Defender Service, WinDefend, ""C:\Program Files\Windows Defender\MsMpEng.exe"" [MS] 
Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS] 
 
 
Print Monitors: 
--------------- 
 
HKLM\System\CurrentControlSet\Control\Print\Monitors\ 
EPSON 1394.3 Monitor\Driver = "epppdtmn.dll" ["SEIKO EPSON CORPORATION"] 
EPSON V5 2KMonitor\Driver = "EBPMON2.DLL" ["SEIKO EPSON CORPORATION"] 
Microsoft Document Imaging Writer Monitor\Driver = "mdimon.dll" [MS] 
 
 
---------- 
+ This report excludes default entries except where indicated. 
+ To see *everywhere* the script checks and *everything* it finds, 
  launch it from a command prompt or a shortcut with the -all parameter. 
+ The search for DESKTOP.INI DLL launch points on all local fixed drives 
  took 28 seconds. 
+ The search for all Registry CLSIDs containing dormant Explorer Bars 
  took 33 seconds. 
---------- (total run time: 228 seconds) 
Marsh Posté le 14-04-2006 à 19:29:12
Supprime cette valeur  ("System" ) : 
 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\  
"System" 
Marsh Posté le 14-04-2006 à 21:00:36
D'accord mais je fais ça comment? Je trouve ça ou? 
 
Sinon d'une manière générale il semblerais que le problème soit réglé mais j'attend 2-3jours avant de crier victoire...
Marsh Posté le 14-04-2006 à 21:01:11
Logfile of HijackThis v1.99.1 
Scan saved at 20:56:03, on 14/04/2006 
Platform: Windows XP SP2 (WinNT 5.01.2600) 
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) 
 
Running processes: 
C:\WINDOWS\System32\smss.exe 
C:\WINDOWS\system32\winlogon.exe 
C:\WINDOWS\system32\services.exe 
C:\WINDOWS\system32\lsass.exe 
C:\WINDOWS\system32\svchost.exe 
C:\Program Files\Windows Defender\MsMpEng.exe 
C:\WINDOWS\System32\svchost.exe 
C:\Program Files\Ahead\InCD\InCDsrv.exe 
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe 
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe 
C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe 
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe 
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe 
C:\WINDOWS\system32\spoolsv.exe 
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe 
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe 
C:\WINDOWS\system32\CTsvcCDA.EXE 
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe 
C:\Program Files\ewido anti-malware\ewidoctrl.exe 
C:\Program Files\ewido anti-malware\ewidoguard.exe 
C:\WINDOWS\System32\GEARSec.exe 
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe 
C:\Program Files\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe 
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe 
C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\VProSvc.exe 
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE 
c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe 
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe 
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE 
C:\WINDOWS\system32\svchost.exe 
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe 
C:\WINDOWS\system32\Tablet.exe 
C:\Program Files\Canon\CAL\CALMAIN.exe 
C:\WINDOWS\Explorer.EXE 
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe 
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe 
C:\Program Files\Logitech\iTouch\iTouch.exe 
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe 
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE 
C:\WINDOWS\system32\CTHELPER.EXE 
C:\WINDOWS\System32\svchost.exe 
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe 
C:\Program Files\Ahead\InCD\InCD.exe 
C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe 
C:\Program Files\Logitech\MouseWare\system\em_exec.exe 
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe 
C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe 
C:\WINDOWS\system32\LVCOMSX.EXE 
C:\Program Files\Logitech\Video\CameraAssistant.exe 
C:\WINDOWS\system32\ElkCtrl.exe 
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe 
C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe 
C:\Program Files\Picasa2\PicasaMediaDetector.exe 
C:\WINDOWS\MXOALDR.EXE 
C:\Program Files\Windows Defender\MSASCui.exe 
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe 
C:\Program Files\iTunes\iTunesHelper.exe 
C:\Program Files\QuickTime\qttask.exe 
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe 
C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe 
C:\WINDOWS\system32\ctfmon.exe 
C:\Program Files\iPod\bin\iPodService.exe 
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe 
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe 
C:\Program Files\Skype\Phone\Skype.exe 
C:\WINDOWS\system32\rundll32.exe 
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe 
C:\Program Files\Fichiers communs\DataViz\DvzIncMsgr.exe 
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe 
C:\Program Files\Google\Google Updater\1.1.433.23491\GoogleUpdater.exe 
C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe 
C:\Program Files\palmOne\Hotsync.exe 
C:\Program Files\Belkin\Nostromo\nost_LM.exe 
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe 
C:\WINDOWS\system32\WTablet\TabUserW.exe 
C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE 
C:\Program Files\Internet Explorer\IEXPLORE.EXE 
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe 
C:\Program Files\Messenger\msmsgs.exe 
C:\Documents and Settings\Niko\Bureau\HijackThis.exe 
 
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens 
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll 
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll 
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll 
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll 
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll 
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll 
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe 
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe 
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe 
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r 
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE" 
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE 
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE 
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe 
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" 
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe 
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe 
O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe 
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" 
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime 
O4 - HKLM\..\Run: [PMCS] C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe -host -clearDebug 
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg 
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE 
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe 
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect 
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation 
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe 
O4 - HKLM\..\Run: [RetroExpress] C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe /h 
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe 
O4 - HKLM\..\Run: [MXOBG] C:\WINDOWS\MXOALDR.EXE 
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide 
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot 
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" 
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime 
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" 
O4 - HKLM\..\Run: [Norton Ghost 10.0] "C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe" 
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe 
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R 
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe 
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe 
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized 
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot 
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1 
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe 
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Fichiers communs\DataViz\DvzIncMsgr.exe 
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE 
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\1.1.433.23491\GoogleUpdater.exe 
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe 
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe 
O4 - Global Startup: Loadout Manager.lnk = C:\Program Files\Belkin\Nostromo\nost_LM.exe 
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe 
O4 - Global Startup: MonacoGamma.lnk = C:\Program Files\Monaco Systems\MonacoEZcolor 2.6\MonacoGamma.exe 
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe 
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe 
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html 
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html 
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html 
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html 
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html 
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html 
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll 
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll 
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk 
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk 
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL 
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe 
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe 
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6 [...] vSniff.cab 
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6 [...] /cabsa.cab 
O17 - HKLM\System\CCS\Services\Tcpip\..\{2F1A6493-4B90-4604-B862-C70FB5547536}: NameServer = 85.255.113.94,85.255.112.225 
O17 - HKLM\System\CCS\Services\Tcpip\..\{2F1B44D1-963C-46F1-8D7B-21076CFBD81B}: NameServer = 85.255.113.94,85.255.112.225 
O17 - HKLM\System\CCS\Services\Tcpip\..\{AEE26DF8-96E8-4372-8E65-F884314A876A}: NameServer = 85.255.113.94,85.255.112.225 
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) 
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) 
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe 
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe 
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe 
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe 
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe 
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe 
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe 
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe 
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe 
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE 
O23 - Service: Pinnacle Systems tvtv Spooler (EpgSpooler) - - c:\progra~1\pinnacle\mediac~1\epgspo~2.exe 
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe 
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe 
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe 
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe 
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe 
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe 
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe 
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe 
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe 
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe 
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE 
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe 
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe 
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\VProSvc.exe 
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE 
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE 
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe 
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe 
O23 - Service: Assistant Retrospect (RetroExp Helper) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\rthlpsvc.exe 
O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe 
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe 
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe 
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe 
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE 
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe 
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe 
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing) 
Marsh Posté le 14-04-2006 à 21:01:29
SmitFraudFix v2.29 
 
Rapport fait à 20:56:35,40, 14/04/2006 
Executé à partir de C:\Program Files\SmitfraudFix\SmitfraudFix 
OS: Microsoft Windows XP [version 5.1.2600] 
 
»»»»»»»»»»»»»»»»»»»»»»»» C:\ 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Niko\Application Data 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Niko\Favoris 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» Bureau 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files  
 
 
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau 
 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler 
 
SrchSTS.exe by S!Ri 
Search SharedTaskScheduler's .dll 
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] 
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui" 
 
[HKEY_CLASSES_ROOT\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32] 
@="%SystemRoot%\system32\browseui.dll" 
 
[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32] 
@="%SystemRoot%\system32\browseui.dll" 
 
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] 
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant" 
 
[HKEY_CLASSES_ROOT\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32] 
@="%SystemRoot%\system32\browseui.dll" 
 
[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32] 
@="%SystemRoot%\system32\browseui.dll" 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» Fin 
Marsh Posté le 14-04-2006 à 21:19:24
"Silent Runners.vbs", revision 44, http://www.silentrunners.org/ 
Operating System: Windows XP SP2 
Output limited to non-default values, except where indicated by "{++}" 
 
 
Startup items buried in registry: 
--------------------------------- 
 
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} 
"CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS] 
"Creative Detector" = ""C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R" ["Creative Technology Ltd"] 
"LDM" = "\Program\BackWeb-8876480.exe" [file not found] 
"(Default)" = (empty string) 
"ATI Remote Control" = "C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe" ["ATI Technologies Inc."] 
"Skype" = ""C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized" ["Skype Technologies S.A."] 
"LogitechSoftwareUpdate" = ""C:\Program Files\Logitech\Video\ManifestEngine.exe" boot" ["Logitech Inc."] 
"updateMgr" = ""C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1" ["Adobe Systems Incorporated"] 
 
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} 
"SunJavaUpdateSched" = "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [null data] 
"IAAnotif" = "C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe" ["Intel Corporation"] 
"zBrowser Launcher" = "C:\Program Files\Logitech\iTouch\iTouch.exe" ["Logitech Inc."] 
"CTSysVol" = "C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r" ["Creative Technology Ltd"] 
"CTDVDDET" = ""C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE"" ["Creative Technology Ltd"] 
"CTHelper" = "CTHELPER.EXE" ["Creative Technology Ltd"] 
"UpdReg" = "C:\WINDOWS\UpdReg.EXE" ["Creative Technology Ltd."] 
"Logitech Utility" = "Logi_MwX.Exe" ["Logitech Inc."] 
"DVDLauncher" = ""C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"" ["CyberLink Corp."] 
"NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"] 
"InCD" = "C:\Program Files\Ahead\InCD\InCD.exe" ["Nero AG"] 
"EEventManager" = "C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe" [empty string] 
"ATIPTA" = ""C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"" ["ATI Technologies, Inc."] 
"ATICCC" = ""C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime" [null data] 
"PMCS" = "C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe -host -clearDebug" [null data] 
"PinnacleDriverCheck" = "C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg" [empty string] 
"LVCOMSX" = "C:\WINDOWS\system32\LVCOMSX.EXE" ["Logitech Inc."] 
"LogitechCameraAssistant" = "C:\Program Files\Logitech\Video\CameraAssistant.exe" ["Logitech Inc."] 
"LogitechVideo[inspector]" = "C:\Program Files\Logitech\Video\InstallHelper.exe /inspect" ["Logitech Inc."] 
"LogitechCameraService(E)" = "C:\WINDOWS\system32\ElkCtrl.exe /automation" ["Logitech Inc."] 
"MaxtorOneTouch" = "C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe" ["Maxtor Corporation"] 
"RetroExpress" = "C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe /h" [null data] 
"Picasa Media Detector" = "C:\Program Files\Picasa2\PicasaMediaDetector.exe" ["Google Inc."] 
"MXOBG" = "C:\WINDOWS\MXOALDR.EXE" ["Cypress Semiconductor"] 
"Windows Defender" = ""C:\Program Files\Windows Defender\MSASCui.exe" -hide" [MS] 
"TkBellExe" = ""C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot" ["RealNetworks, Inc."] 
"iTunesHelper" = ""C:\Program Files\iTunes\iTunesHelper.exe"" ["Apple Computer, Inc."] 
"QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."] 
"ccApp" = ""C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"" ["Symantec Corporation"] 
"Norton Ghost 10.0" = ""C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe"" ["Symantec Corporation"] 
 
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ 
{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided) 
-> {HKLM...CLSID} = (no title provided) 
\InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"] 
{9ECB9560-04F9-4bbc-943D-298DDF1699E1}\(Default) = "Norton Internet Security 2006" 
-> {HKLM...CLSID} = "CNisExtBho Class" 
\InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll" ["Symantec Corporation"] 
{A8F38D8D-E480-4D52-B7A2-731BB6995FDD}\(Default) = "NAV Helper" 
-> {HKLM...CLSID} = "CNavExtBho Class" 
\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"] 
 
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ 
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal" 
-> {HKLM...CLSID} = "HyperTerminal Icon Ext" 
\InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."] 
"{BB7DF450-F119-11CD-8465-00AA00425D90}" = "Microsoft Access Custom Icon Handler" 
-> {HKLM...CLSID} = (no title provided) 
\InProcServer32\(Default) = "C:\Program Files\msaccrt\Access 97\soa800.dll" [MS] 
"{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices" 
-> {HKLM...CLSID} = "Portable Media Devices" 
\InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS] 
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu" 
-> {HKLM...CLSID} = "Portable Media Devices Menu" 
\InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS] 
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player" 
-> {HKLM...CLSID} = "RealOne Player Context Menu Class" 
\InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."] 
"{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}" = "iTunes" 
-> {HKLM...CLSID} = "iTunes" 
\InProcServer32\(Default) = "C:\Program Files\iTunes\iTunesMiniPlayer.dll" ["Apple Computer, Inc."] 
"{950FF917-7A57-46BC-8017-59D9BF474000}" = "Shell Extension for CDRW" 
-> {HKLM...CLSID} = "Shell Extension for CDRW" 
\InProcServer32\(Default) = "C:\Program Files\Ahead\InCD\incdshx.dll" ["Nero AG"] 
"{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler" 
-> {HKLM...CLSID} = "Microsoft Office Outlook" 
\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL" [MS] 
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler" 
-> {HKLM...CLSID} = "Outlook File Icon Extension" 
\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL" [MS] 
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler" 
-> {HKLM...CLSID} = (no title provided) 
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\OFFICE11\msohev.dll" [MS] 
"{5E2121EE-0300-11D4-8D3B-444553540000}" = "Catalyst Context Menu extension" 
-> {HKLM...CLSID} = "SimpleShlExt Class" 
\InProcServer32\(Default) = "C:\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll" [empty string] 
"{7059DA7A-7E60-11d2-A355-00C04FB9D26E}" = "Maxtor Locked Drives" 
-> {HKLM...CLSID} = "Maxtor Locked Drives" 
\InProcServer32\(Default) = "C:\WINDOWS\system32\MXONmSpace.dll" [null data] 
"{21569614-B795-46b1-85F4-E737A8DC09AD}" = "Shell Search Band" 
-> {HKLM...CLSID} = "Shell Search Band" 
\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS] 
"{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders" 
-> {HKLM...CLSID} = "Mes dossiers de partage" 
\InProcServer32\(Default) = "C:\PROGRA~1\MSNMES~1\fsshext.dll" [MS] 
"{EE337094-9F50-4B8C-9B53-C00F52A3289B}" = "GF Shell Extension" 
-> {HKLM...CLSID} = "GFIconShellEx Class" 
\InProcServer32\(Default) = "C:\Program Files\Fichiers communs\onOne Software Shared\lt_lib_gf_iconShellEx.dll" ["onOne Software"] 
 
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\ 
INFECTION WARNING! "{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}" = "Microsoft AntiMalware ShellExecuteHook" 
-> {HKLM...CLSID} = "Microsoft AntiMalware ShellExecuteHook" 
\InProcServer32\(Default) = "C:\PROGRA~1\WIFD1F~1\MpShHook.dll" [MS] 
INFECTION WARNING! "{54D9498B-CF93-414F-8984-8CE7FDE0D391}" = "ewido shell guard" 
-> {HKLM...CLSID} = "CShellExecuteHookImpl Object" 
\InProcServer32\(Default) = "C:\Program Files\ewido anti-malware\shellhook.dll" ["TODO: <Firmenname>"] 
 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\ 
"System" = (value not set) 
 
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ 
INFECTION WARNING! AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."] 
 
HKLM\Software\Classes\PROTOCOLS\Filter\ 
INFECTION WARNING! text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}" 
-> {HKLM...CLSID} = (no title provided) 
\InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [MS] 
 
HKLM\Software\Classes\Folder\shellex\ColumnHandlers\ 
{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info" 
-> {HKLM...CLSID} = "PDF Shell Extension" 
\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."] 
 
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ 
ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}" 
-> {HKLM...CLSID} = "Ctest Object" 
\InProcServer32\(Default) = "C:\Program Files\ewido anti-malware\context.dll" ["ewido networks"] 
Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{FAD61B3D-699D-49B2-BE16-7F82CB4C59CA}" 
-> {HKLM...CLSID} = "IEContextMenu Class" 
\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"] 
 
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ 
ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}" 
-> {HKLM...CLSID} = "Ctest Object" 
\InProcServer32\(Default) = "C:\Program Files\ewido anti-malware\context.dll" ["ewido networks"] 
 
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ 
Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{FAD61B3D-699D-49B2-BE16-7F82CB4C59CA}" 
-> {HKLM...CLSID} = "IEContextMenu Class" 
\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"] 
 
 
Default executables: 
-------------------- 
 
HKCU\Software\Classes\.bat\(Default) = (value not set) 
 
HKCU\Software\Classes\.cmd\(Default) = (value not set) 
 
HKCU\Software\Classes\.com\(Default) = (value not set) 
 
HKCU\Software\Classes\.exe\(Default) = (value not set) 
 
HKCU\Software\Classes\.hta\(Default) = (value not set) 
 
 
Active Desktop and Wallpaper: 
----------------------------- 
 
Active Desktop is disabled at this entry: 
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState 
 
 
Startup items in "Niko" & "All Users" startup folders: 
------------------------------------------------------ 
 
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage 
"ATI CATALYST System Tray" -> shortcut to: "C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe SystemTray" [null data] 
"DataViz Inc Messenger" -> shortcut to: "C:\Program Files\Fichiers communs\DataViz\DvzIncMsgr.exe" ["DataViz, Inc."] 
"EPSON Status Monitor 3 Environment Check 2" -> shortcut to: "C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE" ["SEIKO EPSON CORPORATION"] 
"Google Updater" -> shortcut to: "C:\Program Files\Google\Google Updater\1.1.433.23491\GoogleUpdater.exe -systray -startup" [null data] 
"HotSync Manager" -> shortcut to: "C:\Program Files\palmOne\Hotsync.exe -logon" ["PalmSource, Inc"] 
"Lancement rapide d'Adobe Reader" -> shortcut to: "C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe" ["Adobe Systems Incorporated"] 
"Loadout Manager" -> shortcut to: "C:\Program Files\Belkin\Nostromo\nost_LM.exe -startup" [empty string] 
"Logitech Desktop Messenger" -> shortcut to: "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe /start" ["Logitech"] 
"MonacoGamma" -> shortcut to: "C:\Program Files\Monaco Systems\MonacoEZcolor 2.6\MonacoGamma.exe -StartUp -All" ["Monaco Systems"] 
"Service Manager" -> shortcut to: "C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe /n" [MS] 
"TabUserW.exe" -> shortcut to: "C:\WINDOWS\system32\WTablet\TabUserW.exe" ["Wacom Technology, Corp."] 
 
 
Enabled Scheduled Tasks: 
------------------------ 
 
"MP Scheduled Scan" -> launches: "C:\Program Files\Windows Defender\MpCmdRun.exe Scan -ScanType config -Privileges restricted" [MS] 
"Norton AntiVirus - Effectuer une analyse complète du système - Niko" -> launches: "C:\PROGRA~1\NORTON~2\NORTON~1\Navw32.exe /TASK:"C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Tasks\mycomp.sca"" ["Symantec Corporation"] 
"Norton AntiVirus - Exécuter Norton QuickScan - Niko" -> launches: "C:\PROGRA~1\NORTON~2\NORTON~1\Navw32.exe /TASK:"C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Tasks\quick.sca"" ["Symantec Corporation"] 
 
 
Winsock2 Service Provider DLLs: 
------------------------------- 
 
Namespace Service Providers 
 
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] 
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS] 
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] 
 
Transport Service Providers 
 
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: 
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 26 
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05 
 
 
Toolbars, Explorer Bars, Extensions: 
------------------------------------ 
 
Toolbars 
 
HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\ 
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" 
-> {HKLM...CLSID} = "&Google" 
\InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."] 
 
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ 
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}" 
-> {HKLM...CLSID} = "Norton Internet Security 2006" 
\InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll" ["Symantec Corporation"] 
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" 
-> {HKLM...CLSID} = "&Google" 
\InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."] 
"{C4069E3A-68F1-403E-B40E-20066696354B}" 
-> {HKLM...CLSID} = "Norton AntiVirus" 
\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"] 
 
HKLM\Software\Microsoft\Internet Explorer\Toolbar\ 
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = (no title provided) 
-> {HKLM...CLSID} = "&Google" 
\InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."] 
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}" = "Norton Internet Security 2006" 
-> {HKLM...CLSID} = "Norton Internet Security 2006" 
\InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll" ["Symantec Corporation"] 
"{C4069E3A-68F1-403E-B40E-20066696354B}" = "Norton AntiVirus" 
-> {HKLM...CLSID} = "Norton AntiVirus" 
\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"] 
 
Explorer Bars 
 
Dormant Explorer Bars in "View, Explorer Bar" menu 
 
HKLM\Software\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Rechercher" 
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar] 
InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL" [MS] 
 
Extensions (Tools menu items, main toolbar menu buttons) 
 
HKLM\Software\Microsoft\Internet Explorer\Extensions\ 
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ 
"MenuText" = "Console Java (Sun)" 
"CLSIDExtension" = "{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" 
 
{5E638779-1818-4754-A595-EF1C63B87A56}\ 
"ButtonText" = "Express Cleanup" 
"MenuText" = "Express Cleanup" 
"Exec" = "C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk" [null data] 
 
{92780B25-18CC-41C8-B9BE-3C9C571A8263}\ 
"ButtonText" = "Recherche" 
 
{FB5F1910-F110-11D2-BB9E-00C04F795683}\ 
"ButtonText" = "Messenger" 
"MenuText" = "Windows Messenger" 
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS] 
 
 
Miscellaneous IE Hijack Points 
------------------------------ 
 
C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings" ) 
 
Added lines (compared with English-language version): 
[Strings]: SAFESITE_VALUE="http://home.microsoft.com/intl/fr/" 
 
Missing lines (compared with English-language version): 
[Strings]: 1 line 
 
 
Running Services (Display Name, Service Name, Path {Service DLL}): 
------------------------------------------------------------------ 
 
Canon Camera Access Library 8, CCALib8, "C:\Program Files\Canon\CAL\CALMAIN.exe" ["Canon Inc."] 
Creative Service for CDROM Access, Creative Service for CDROM Access, "C:\WINDOWS\system32\CTsvcCDA.EXE" ["Creative Technology Ltd"] 
EPSON Printer Status Agent2, EPSONStatusAgent2, "C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe" ["SEIKO EPSON CORPORATION"] 
EpsonBidirectionalService, EpsonBidirectionalService, "C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe" [null data] 
ewido security suite control, ewido security suite control, "C:\Program Files\ewido anti-malware\ewidoctrl.exe" ["ewido networks"] 
ewido security suite guard, ewido security suite guard, "C:\Program Files\ewido anti-malware\ewidoguard.exe" ["ewido networks"] 
GEARSecurity, GEARSecurity, "C:\WINDOWS\System32\GEARSec.exe" ["GEAR Software"] 
HTTP SSL, HTTPFilter, "C:\WINDOWS\System32\svchost.exe -k HTTPFilter" {"C:\WINDOWS\System32\w3ssl.dll" [MS]} 
IAA Event Monitor, IAANTMon, "C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe" ["Intel Corporation"] 
InCD Helper, InCDsrv, "C:\Program Files\Ahead\InCD\InCDsrv.exe" ["Nero AG"] 
iPodService, iPodService, "C:\Program Files\iPod\bin\iPodService.exe" ["Apple Computer, Inc."] 
Logitech Process Monitor, LVPrcSrv, "c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe" ["Logitech Inc."] 
MSSQL$PINNACLESYS, MSSQL$PINNACLESYS, "C:\Program Files\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe -sPINNACLESYS" [MS] 
Norton Ghost, Norton Ghost, "C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\VProSvc.exe" ["Symantec Corporation"] 
Norton Protection Center Service, NSCService, ""C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE"" ["Symantec Corporation"] 
Norton UnErase Protection, NProtectService, "C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE" ["Symantec Corporation"] 
Pinnacle Systems Media Service, PinnacleSys.MediaServer, "c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe" [null data] 
Pinnacle Systems tvtv Spooler, EpgSpooler, "c:\progra~1\pinnacle\mediac~1\epgspo~2.exe" [null data] 
Planificateur LiveUpdate automatique, Planificateur LiveUpdate automatique, ""C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"" ["Symantec Corporation"] 
Retrospect Express HD Launcher, RetroExpLauncher, "C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe" ["Dantz Development Corporation"] 
Service d'application d'assistance IPv6, 6to4, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\6to4svc.dll" [MS]} 
Service Norton AntiVirus Auto-Protect, navapsvc, ""C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe"" ["Symantec Corporation"] 
Speed Disk service, Speed Disk service, "C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE" ["Symantec Corporation"] 
Symantec Core LC, Symantec Core LC, "C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe" ["Symantec Corporation"] 
Symantec Event Manager, ccEvtMgr, ""C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe"" ["Symantec Corporation"] 
Symantec Network Drivers Service, SNDSrvc, ""C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe"" ["Symantec Corporation"] 
Symantec Network Proxy, ccProxy, ""C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe"" ["Symantec Corporation"] 
Symantec Settings Manager, ccSetMgr, ""C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe"" ["Symantec Corporation"] 
Symantec SPBBCSvc, SPBBCSvc, ""C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe"" ["Symantec Corporation"] 
TabletService, TabletService, "C:\WINDOWS\system32\Tablet.exe" ["Wacom Technology, Corp."] 
Windows Defender Service, WinDefend, ""C:\Program Files\Windows Defender\MsMpEng.exe"" [MS] 
Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS] 
 
 
Print Monitors: 
--------------- 
 
HKLM\System\CurrentControlSet\Control\Print\Monitors\ 
EPSON 1394.3 Monitor\Driver = "epppdtmn.dll" ["SEIKO EPSON CORPORATION"] 
EPSON V5 2KMonitor\Driver = "EBPMON2.DLL" ["SEIKO EPSON CORPORATION"] 
Microsoft Document Imaging Writer Monitor\Driver = "mdimon.dll" [MS] 
 
 
---------- 
+ This report excludes default entries except where indicated. 
+ To see *everywhere* the script checks and *everything* it finds, 
launch it from a command prompt or a shortcut with the -all parameter. 
+ The search for DESKTOP.INI DLL launch points on all local fixed drives 
took 77 seconds. 
+ The search for all Registry CLSIDs containing dormant Explorer Bars 
took 25 seconds. 
---------- (total run time: 154 seconds) 
 
Marsh Posté le 14-04-2006 à 22:28:17
Voici le résultat d'une analyse en ligne avec Kaspersky: 
 
------------------------------------------------------------------------------- 
 KASPERSKY ON-LINE SCANNER REPORT 
 Friday, April 14, 2006 10:27:21 PM 
 Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) 
 Kaspersky On-line Scanner version: 5.0.78.0 
 Kaspersky Anti-Virus database last update: 14/04/2006 
 Kaspersky Anti-Virus database records: 188148 
------------------------------------------------------------------------------- 
 
Scan Settings: 
 Scan using the following antivirus database: extended 
 Scan Archives: true 
 Scan Mail Bases: true 
 
Scan Target - My Computer: 
 A:\ 
 C:\ 
 D:\ 
 E:\ 
 F:\ 
 G:\ 
 I:\ 
 J:\ 
 K:\ 
 
Scan Statistics: 
 Total number of scanned objects: 119426 
 Number of viruses found: 4 
 Number of infected objects: 7 
 Number of suspicious objects: 0 
 Duration of the scan process: 00:53:36 
 
Infected Object Name / Virus Name / Last Action 
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\00D94F2E.zip/BlackBox.class	Infected: Exploit.Java.ByteVerify	skipped 
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\00D94F2E.zip/VerifierBug.class	Infected: Exploit.Java.ByteVerify	skipped 
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\00D94F2E.zip/Beyond.class	Infected: Trojan-Downloader.Java.OpenConnection.aa	skipped 
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\00D94F2E.zip	ZIP: infected - 3	skipped 
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\00D94F2E.zip	CryptFF: infected - 3	skipped 
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0220733B.exe	Infected: Trojan.Win32.Small.hl	skipped 
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\12591918.exe	Infected: Trojan-Clicker.Win32.Small.kg	skipped 
 
Scan process completed. 
Marsh Posté le 14-04-2006 à 23:24:10
Non, l'ordnateur était bien infecté par WareOut... 
 
Ceci est typique : 
O17 - HKLM\System\CCS\Services\Tcpip\..\{2F1A6493-4B90-4604-B862-C70FB5547536}: NameServer = 85.255.113.94,85.255.112.225  
O17 - HKLM\System\CCS\Services\Tcpip\..\{2F1B44D1-963C-46F1-8D7B-21076CFBD81B}: NameServer = 85.255.113.94,85.255.112.225  
O17 - HKLM\System\CCS\Services\Tcpip\..\{AEE26DF8-96E8-4372-8E65-F884314A876A}: NameServer = 85.255.113.94,85.255.112.225  
 
85.255.112.225  t'envoie vers : 
85.255.112.0 - 85.255.127.255 
Inhoster hosting company 
OOO Inhoster, Poltavskij Shliax 24, Kharkiv, 61000, Ukraine 
 
If faut fixer ces lignes.
Marsh Posté le 17-04-2006 à 13:19:35
J'ai changé de pseudo mais c'est encore moi... 
 
Merci, j'ai fixé les lignes. 
 
J'envois les derniers rapports pour votre expertise mais apparemment tout est rentré dans l'ordre. 
Marsh Posté le 17-04-2006 à 13:19:55
SmitFraudFix v2.29 
 
Rapport fait à 14:27:43,50, 15/04/2006 
Executé à partir de C:\Program Files\SmitfraudFix\SmitfraudFix 
OS: Microsoft Windows XP [version 5.1.2600] 
 
»»»»»»»»»»»»»»»»»»»»»»»» C:\ 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Niko\Application Data 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Niko\Favoris 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» Bureau 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files  
 
 
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau 
  
  
 
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler 
 
SrchSTS.exe by S!Ri 
Search SharedTaskScheduler's .dll 
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] 
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui" 
 
[HKEY_CLASSES_ROOT\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32] 
@="%SystemRoot%\system32\browseui.dll" 
 
[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32] 
@="%SystemRoot%\system32\browseui.dll" 
 
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] 
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant" 
 
[HKEY_CLASSES_ROOT\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32] 
@="%SystemRoot%\system32\browseui.dll" 
 
[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32] 
@="%SystemRoot%\system32\browseui.dll" 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll 
 
 
»»»»»»»»»»»»»»»»»»»»»»»» Fin 
 
Marsh Posté le 17-04-2006 à 13:20:14
Logfile of HijackThis v1.99.1 
Scan saved at 14:28:24, on 15/04/2006 
Platform: Windows XP SP2 (WinNT 5.01.2600) 
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) 
 
Running processes: 
C:\WINDOWS\System32\smss.exe 
C:\WINDOWS\system32\winlogon.exe 
C:\WINDOWS\system32\services.exe 
C:\WINDOWS\system32\lsass.exe 
C:\WINDOWS\system32\Ati2evxx.exe 
C:\WINDOWS\system32\svchost.exe 
C:\Program Files\Windows Defender\MsMpEng.exe 
C:\WINDOWS\System32\svchost.exe 
C:\Program Files\Ahead\InCD\InCDsrv.exe 
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe 
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe 
C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe 
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe 
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe 
C:\WINDOWS\system32\spoolsv.exe 
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe 
C:\WINDOWS\system32\Ati2evxx.exe 
C:\WINDOWS\Explorer.EXE 
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe 
C:\WINDOWS\system32\CTsvcCDA.EXE 
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe 
C:\Program Files\ewido anti-malware\ewidoctrl.exe 
C:\Program Files\ewido anti-malware\ewidoguard.exe 
C:\WINDOWS\System32\GEARSec.exe 
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe 
C:\Program Files\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe 
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe 
C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\VProSvc.exe 
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE 
c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe 
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe 
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe 
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe 
C:\Program Files\Logitech\iTouch\iTouch.exe 
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe 
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE 
C:\WINDOWS\system32\CTHELPER.EXE 
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe 
C:\Program Files\Logitech\MouseWare\system\em_exec.exe 
C:\Program Files\Ahead\InCD\InCD.exe 
C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe 
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe 
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE 
C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe 
C:\WINDOWS\system32\svchost.exe 
C:\WINDOWS\system32\LVCOMSX.EXE 
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe 
C:\Program Files\Logitech\Video\CameraAssistant.exe 
C:\WINDOWS\system32\Tablet.exe 
C:\WINDOWS\system32\ElkCtrl.exe 
C:\Program Files\Canon\CAL\CALMAIN.exe 
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe 
C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe 
C:\Program Files\Picasa2\PicasaMediaDetector.exe 
C:\WINDOWS\MXOALDR.EXE 
C:\Program Files\Windows Defender\MSASCui.exe 
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe 
C:\Program Files\iTunes\iTunesHelper.exe 
C:\Program Files\QuickTime\qttask.exe 
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe 
C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe 
C:\WINDOWS\system32\ctfmon.exe 
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe 
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe 
C:\Program Files\iPod\bin\iPodService.exe 
C:\WINDOWS\system32\rundll32.exe 
C:\Program Files\Skype\Phone\Skype.exe 
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe 
C:\WINDOWS\System32\svchost.exe 
C:\Program Files\Fichiers communs\DataViz\DvzIncMsgr.exe 
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe 
C:\Program Files\Google\Google Updater\1.1.433.23491\GoogleUpdater.exe 
C:\Program Files\palmOne\Hotsync.exe 
C:\Program Files\Belkin\Nostromo\nost_LM.exe 
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe 
C:\WINDOWS\system32\WTablet\TabUserW.exe 
C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE 
C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe 
C:\Program Files\Messenger\msmsgs.exe 
C:\Documents and Settings\Niko\Bureau\HijackThis.exe 
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =  
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =  
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens 
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll 
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll 
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll 
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll 
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll 
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll 
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe 
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe 
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe 
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r 
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE" 
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE 
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE 
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe 
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" 
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe 
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe 
O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe 
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" 
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime 
O4 - HKLM\..\Run: [PMCS] C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe -host -clearDebug 
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg 
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE 
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe 
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect 
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation 
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe 
O4 - HKLM\..\Run: [RetroExpress] C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe /h 
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe 
O4 - HKLM\..\Run: [MXOBG] C:\WINDOWS\MXOALDR.EXE 
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide 
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe"  -osboot 
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" 
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime 
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" 
O4 - HKLM\..\Run: [Norton Ghost 10.0] "C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe" 
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe 
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R 
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe 
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe 
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized 
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot 
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1 
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe 
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Fichiers communs\DataViz\DvzIncMsgr.exe 
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE 
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\1.1.433.23491\GoogleUpdater.exe 
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe 
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe 
O4 - Global Startup: Loadout Manager.lnk = C:\Program Files\Belkin\Nostromo\nost_LM.exe 
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe 
O4 - Global Startup: MonacoGamma.lnk = C:\Program Files\Monaco Systems\MonacoEZcolor 2.6\MonacoGamma.exe 
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe 
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe 
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html 
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html 
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html 
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html 
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html 
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html 
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll 
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll 
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk 
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk 
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL 
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe 
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe 
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/engli [...] nicode.cab 
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6 [...] vSniff.cab 
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.ya [...] 040510.cab 
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6 [...] /cabsa.cab 
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) 
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) 
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe 
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe 
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe 
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe 
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe 
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe 
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe 
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe 
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe 
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE 
O23 - Service: Pinnacle Systems tvtv Spooler (EpgSpooler) -   - c:\progra~1\pinnacle\mediac~1\epgspo~2.exe 
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe 
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe 
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe 
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe 
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe 
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe 
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe 
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe 
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe 
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe 
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE 
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe 
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe 
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\VProSvc.exe 
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE 
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE 
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe 
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe 
O23 - Service: Assistant Retrospect (RetroExp Helper) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\rthlpsvc.exe 
O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe 
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe 
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe 
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe 
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE 
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe 
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe 
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing) 
 
Marsh Posté le 14-04-2006 à 15:55:48
Bonjour,
Jai 2 soucis dont je narrive pas à me débarrasser :
-Trojan.Pakes (que je trouve avec Ewido)
-Pipas.A (que je trouve avec Spybot)
Comme « symptômes » il marrive dêtre redirigé vers des pas que je nai pas demandés (genre je cherche à aller sur le site de Symantec et je me retrouve sur celui dun antivirus louche ou vers Lycos alors que je nai rien demandé)
Jai eu une infection y as4-5 jours depuis jai croisé Vcodec, Smitfraud-c, Spywarequake, Zlob .downloder et des trackingcookie.weborama dont je me suis débarrassé tant bien que mal mais Trojan.Pakes et Pipas.A résistent.
Je suis reste quelques jours sans antivirus ni par feu (enfin si mais périmé depuis 2004 ) suite à une première infection.
J utilise Ad-Aware, Ewido, Spybot, Windows Defender, SpywareBlaster et Norton Systemworks et Internet Security 2006, le tout à jour.
Jai tout lance en mode normal et sans échec jusquà plus rien détecté mais ça reviens toujours au redémarrage suivant
Spybot supprime Pipas.A dans les 2 modes mais Trojan.Pakes résiste à Ewido en mode normal.
Je narrive pas non plus à redémarrer en mode sans échec autrement quen plantant la machine lors du démarrage de Windows (F8 ne marche pas, peut-être parce que jai un clavier sans fil Logitech ? Ou alors faut enfoncer quelque chose pour activer la touche mais comme je ne men sers jamais je ne sais pas quoi )
Donc que faire ?
Jai vu des indications sur des cas similaires mais je ne les comprends pas bien (ancien du monde mac, pas vraiment doué avec un PC ), surtout je vois des indications pour des actions à menée mais il nest jamais expliqué à quoi ça sert, hors je naime pas faire bêtement des trucs sur ma machine sans comprendre
Un dernier souci mais pas le moindre : jai eu à payer des trucs en CB sur internet avec ses infections Y as un risque ?
Merci davance aux bonnes âmes qui pourraient maider !